News

JavaScript packages with billions of downloads were compromised by an unknown threat actor looking to steal cryptocurrency.
An attack targeting the Node.js ecosystem was just identified — but not before it compromised 18 npm packages that account ...
Hackers planted malicious code in open source software packages with more than 2 billion weekly updates in what is likely to ...
Next year’s Java release is slated to include a performance boost for the G1 garbage collector and opt-in support for HTTP/3.
In a supply chain attack, attackers injected malware into NPM packages with over 2.6 billion weekly downloads after ...
At least 18 popular JavaScript code packages that are collectively downloaded more than two billion times each week were briefly compromised with malicious software today, after a developer involved ...
According to ReversingLabs' 2025 Software Supply Chain Security Report, 14 of the 23 crypto-related malicious campaigns in ...
Koi has raised $48 million to help companies protect against software add-ons, which are increasing in usage and can evade traditional protections.